OpenH264 Rust API Openh264 Decoding Functions Heap Overflow Vulnerability
High severity
GitHub Reviewed
Published
Feb 24, 2025
to the GitHub Advisory Database
•
Updated Feb 24, 2025
Description
Published to the GitHub Advisory Database
Feb 24, 2025
Reviewed
Feb 24, 2025
Last updated
Feb 24, 2025
OpenH264 recently reported a heap overflow that was fixed in upstream 63db555 and integrated into our 0.6.6 release. For users relying on Cisco's pre-compiled DLL, we also published 0.8.0, which is compatible with their latest fixed DLL version 2.6.0.
In other words:
source
feature only, >=0.6.6 should be safe,libloading
, you must upgrade to 0.8.0 and use their latest DLL >=2.6.0.Users handling untrusted video files should update immediately.
References